← Consultant Academy
ISO/IEC 42001 LEARNING MAP

AIMS structure for AI Act Ready consultants

This is a training map of the management-system structure and practical evidence you should understand. It does not reproduce the ISO standard. Formal implementation and certification work should use a properly licensed copy of ISO/IEC 42001.

Plan · Do · Check · Act
PLAN

Context + leadership + risks/opportunities + objectives + selected controls.

DO

Resources, competence, communication and operational lifecycle/risk/impact processes.

CHECK

Monitor performance, audit the system and bring results to management review.

ACT

Correct problems, address root causes and improve the management system.

4

Context of the organisation

Why the AIMS exists, its scope, interested parties and the organisational context that shapes AI governance.

Evidence examples: AIMS scope, context analysis, interested-party needs, boundaries and interfaces.
5

Leadership

Leadership commitment, governance direction, policy and clear responsibility for the management system.

Evidence examples: AI policy, leadership decisions, roles/RACI, governance forums and accountability.
6

Planning

Risks and opportunities, objectives, planned changes and the actions needed to achieve responsible AI outcomes.

Evidence examples: Risk methodology/register, objectives, treatment plans, change planning and ownership.
7

Support

Resources, competence, awareness, communication and controlled documented information.

Evidence examples: Competence matrix, literacy/training evidence, communications, document control and resource decisions.
8

Operation

The repeatable operational processes that turn policy and plans into AI risk, impact and lifecycle governance.

Evidence examples: Operational procedures, AI risk assessment/treatment, impact assessments, supplier/lifecycle controls and records.
9

Performance evaluation

How the organisation knows whether the AIMS is working through measurement, internal audit and management review.

Evidence examples: KPIs/monitoring, audit programme and reports, management-review inputs, decisions and action tracking.
10

Improvement

How problems are corrected, causes addressed and the AIMS continually improved.

Evidence examples: Nonconformities, root-cause analysis, corrective actions, effectiveness checks and improvement log.
Annex A control themes

Think in control families, not paperwork

Policies for AI
Internal organisation and accountability
Resources for AI systems
Assessment of impacts of AI systems
AI system lifecycle governance
Data governance
Information for interested parties
Responsible use of AI systems
Third-party and customer relationships

A consultant should be able to explain why a control is relevant, who owns it, how it operates, what evidence exists and how effectiveness is monitored. Annex A should not be treated as a tick-box substitute for risk assessment and organisational context.

Link to EU AI Act work

AIMS evidence can support AI Act readiness — for example inventories, risk processes, data governance, oversight, supplier controls, monitoring and corrective action — but the legal obligations still need their own role, classification and requirement analysis.

Source basis: public ISO description of ISO/IEC 42001 as an AI management-system standard for establishing, implementing, maintaining and continually improving an AIMS using Plan-Do-Check-Act. Use the licensed standard for exact normative requirements.